Internet Explorer  - Y6fW11545292637 - Microsoft Released Security Updates for Internet Explorer zero-day

Microsoft released security updates for remote code exection that exists with , which allows an attacker to execute an arbitary code in the context of the current user.

The vulnerability is tracked as CVE-2018-863. It was identified by Google’s Analysis Group and the vulnerability is currently being exploited in wild.

Microsoft  recently released Security Updates & Fixed 39 Vulnerabilities Including Active Zero-day

The bug can be exploited if the user visited a specially crafted webpage that was designed to exploit the vulnerability through Internet Explorer browser.

An attacker who has successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged in with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

If the attacker takes control over the system, they can utilize it to download additional and execute the with user access.

The vulnerability could corrupt the memory, which allows an attacker to run the an arbitary code remotely. Now Microsoft fixed the Zero-day by modifying the script engine that handles the object.

To fix the vulnerability, Microsoft released a Cumulative security update for Internet Explorer KB4470199 allowing the users to confirm the update by verifying the version of jscript.dll is 5.8.9600.19230.

This update is applicable to Internet Explorer 11 on , Internet Explorer 11 on 8.1 Update, Internet Explorer 11 on 7 SP1, Internet Explorer 10 on Server 2012, Internet Explorer 9 – Embedded Standard 2009 & Embedded POSReady 2009..

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.





Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here